Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44821 2024-06-03 11:07 kano.exe  

e9ac7172d4fe46c82cce7948a264f615


Malicious Packer Anti_VM PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted unpack itself Windows utilities Collect installed applications suspicious process AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 5 8 13.0 M 29 ZeroCERT

44822 2024-06-03 11:14 0329bb5b3a450b0a8f148a57e045bf...  

3c81dc763a4f003ba6e33cd5b63068cd


Generic Malware Antivirus AntiDebug AntiVM MSOffice File Lnk Format HWP GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
7.2 21 ZeroCERT

44823 2024-06-03 12:04 0329bb5b3a450b0a8f148a57e045bf...  

3c81dc763a4f003ba6e33cd5b63068cd


Generic Malware Antivirus AntiDebug AntiVM MSOffice File Lnk Format HWP GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 6.6 21 ZeroCERT

44824 2024-06-03 13:27 김명희_20240515.xlsx.lnk  

0993cf18121be84f5b1511318df80f44


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.2 30 ZeroCERT

44825 2024-06-03 14:00 Job Description (LM HR Divisio...  

73d2899aade924476e58addf26254c2e


Generic Malware Malicious Library Malicious Packer UPX PDF PE64 PE File OS Processor Check DLL DllRegisterServer dll VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities Auto service suspicious process sandbox evasion WriteConsoleW installed browsers check Windows Browser ComputerName DNS DDNS
1 1 1 11.0 49 ZeroCERT

44826 2024-06-03 14:14 Safety Manager JD (General Dyn...  

8346d90508b5d41d151b7098c7a3e868


Client SW User Data Stealer browser info stealer Generic Malware Hide_EXE Google Chrome User Data Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code Browser Info Stealer VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities Auto service suspicious process malicious URLs WriteConsoleW installed browsers check Windows Exploit Browser ComputerName Cryptographic key crashed
1 1 12.6 8 ZeroCERT

44827 2024-06-03 14:26 RFQ#ORDER-SP-24-0217891-003.do...  

527d1b34d5c5759d38b6496008e379b1


NSIS Malicious Library UPX PE File PE32 DLL JPEG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.6 34 ZeroCERT

44828 2024-06-03 14:26 RFQ7834599403 0037JH864_Rev001...  

43f40fde792d50035c3769354a3208c0


NSIS Generic Malware Malicious Library UPX Antivirus PE File PE32 powershell suspicious privilege Check memory Checks debugger WMI Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.2 ZeroCERT

44829 2024-06-03 15:15 RFQ#ORDER-SP-24-0217891-003.do...  

527d1b34d5c5759d38b6496008e379b1


NSIS Malicious Library UPX PE File PE32 VirusTotal Malware
1.2 34 ZeroCERT

44830 2024-06-03 22:19 haspdinst_8_31+(2).exe  

235623c73f1d0283860da85f75d41500


Gen1 Generic Malware Malicious Library Malicious Packer UPX Anti_VM PE File PE32 CAB OS Processor Check DLL VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check
2.4 2 guest

44831 2024-06-03 22:21 RUS_QGYTZ.exe  

5e3bc7cfb4f18e8c55e2808cd0d74bcf


Gen1 Generic Malware Malicious Library UPX Anti_VM PE File PE32 OS Processor Check DLL Checks debugger unpack itself Detects VirtualBox Check virtual network interfaces AppData folder anti-virtualization ComputerName Firmware
4.4 guest

44832 2024-06-03 22:53 python-3.12.3-amd64.exe  

c86949710e0471a065db970290819489


Generic Malware Malicious Library UPX PE File PE32 CAB OS Processor Check PDB Check memory Checks debugger Creates executable files unpack itself
2.0 guest

44833 2024-06-04 07:22 lumma2705.exe  

a09ef83719952de3da58e3af375af664


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
2.8 58 ZeroCERT

44834 2024-06-04 07:22 FrameworkSurvivor.exe  

69f6dcdb3d87392f300e9052de99d7ce


NSIS Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
6.6 10 ZeroCERT

44835 2024-06-04 07:24 %E7%A8%BD%E6%9F%A5%E4%BA%8B%E9...  

6bd7b1da6cecdda481d35391eb2ba24f


Generic Malware Malicious Library Malicious Packer UPX PE64 PE File OS Processor Check VirusTotal Malware MachineGuid unpack itself Tofsee DNS crashed
1 2 3 2.0 13 ZeroCERT